More Info:
Ensure that all your Amazon Elastic Block Store (EBS) volumes are encrypted in order to meet security and compliance requirements. With encryption enabled, your EBS volumes can hold sensitive, confidential, and critical data. The data encryption and decryption process is handled transparently and does not require any additional action from you, your server instance, or your application.Risk Level
MediumAddress
SecurityCompliance Standards
- APRA CPS 234 (Australia)
- AWS Startup Security Baseline
- AWS Well Architected Framework
- BSI C5 (Germany)
- Brazil LGPD
- CCPA / CPRA (California)
- CIS Critical Security Controls v8
- CMMC 2.0
- CSA Cloud Controls Matrix v4
- DPDPA
- Digital Operational Resilience Act (EU)
- GDPR
- HIPAA
- ISO 27001
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- KSA PDPL
- MAS Technology Risk Management (Singapore)
- MITRE ATT&CK (Cloud)
- NIS2 Directive
- NIST CSF
- NIST SP 800-171
- NYDFS 23 NYCRR 500
- PCI
- Reserve Bank of India (RBI) Cyber Security Framework
- SOC2
- SWIFT Customer Security Controls Framework
- Sarbanes-Oxley IT General Controls
- Securities and Exchange Board of India (SEBI) - Cloud Security Adoption Framework
- UK NCSC Cyber Assessment Framework
Triage and Remediation
- Remediation
Remediation
Using Console
Using Console
To remediate the misconfiguration of enabling volume encryption in AWS, you can follow the below steps using the AWS Management Console:
- Open the AWS Management Console and navigate to the EC2 dashboard.
- From the left-hand side menu, select ‘Volumes’.
- Identify the volume that needs to be encrypted and select it.
- From the ‘Actions’ dropdown menu, select ‘Create Snapshot’.
- In the ‘Create Snapshot’ window, provide a name and description for the snapshot and click on ‘Create Snapshot’.
- Once the snapshot is created, select the original volume again and from the ‘Actions’ dropdown menu, select ‘Create Volume’.
- In the ‘Create Volume’ window, select the same availability zone as the original volume, choose the snapshot that was just created, and enable ‘Encryption’ option.
- Click on ‘Create Volume’ to create the new encrypted volume.
- Once the new volume is created, detach the original volume and attach the new encrypted volume to the instance.
- Finally, verify that the new encrypted volume is attached and working properly.
Using CLI
Using CLI
Here are the step by step instructions to enable volume encryption for AWS using AWS CLI:Replace Replace Replace Replace Replace
- Open the AWS CLI on your local machine or EC2 instance.
- Run the following command to enable encryption for a new EBS volume:
<availability-zone> with the availability zone where you want to create the volume and <size> with the size of the volume in GiB.- If you want to enable encryption for an existing EBS volume, you can use the following command:
<volume-id> with the ID of the volume you want to encrypt.- You can also enable encryption for multiple volumes at once using a JSON file. Create a JSON file with the following format:
<volume-id-1> and <volume-id-2> with the IDs of the volumes you want to encrypt.- Save the JSON file and run the following command to enable encryption for the volumes listed in the file:
<path-to-json-file> with the path to the JSON file you created.- Verify that encryption is enabled for your volumes by running the following command:
<volume-id> with the ID of the volume you want to check.You should see "Encrypted": true in the output if encryption is enabled.Using Python
Using Python
To enable volume encryption in AWS using Python, you can follow these steps:Putting it all together, the complete Python code to enable volume encryption in AWS would look like this:Note: This code assumes that you have the necessary permissions to modify volumes in your AWS account.
- Import the necessary libraries:
- Create an EC2 client object:
- Get a list of all the volumes in your account:
- Loop through the volumes and check if they are already encrypted:
- If the volume is not encrypted, enable encryption:
- Print a message indicating that the encryption has been enabled:
- If the volume is already encrypted, print a message indicating that no action was taken:
Using Terraform
Using Terraform
UNENCRYPTED_VOLUME_IDwith the current unencrypted EBS volume ID.SOURCE_REGION_CODEwith the region of the original snapshot/volume (for example,us-east-1).AVAILABILITY_ZONEwith the AZ where the volume must live (for example,us-east-1a).DEVICE_NAMEwith the existing device name on the instance (for example,/dev/sdf).INSTANCE_IDwith the EC2 instance ID.- Optionally set
kms_key_id,size,type, etc., to match your requirements.
terraform plan should show:- creation of
aws_ebs_snapshot.SOURCE_UNENCRYPTED_SNAPSHOT - creation of
aws_ebs_snapshot_copy.ENCRYPTED_SNAPSHOT_COPYwithencrypted = true - creation of
aws_ebs_volume.ENCRYPTED_DATA_VOLUMEfrom the encrypted snapshot - creation of
aws_volume_attachment.ENCRYPTED_DATA_ATTACHMENTattaching the new encrypted volume to the instance - (and, once you delete any old unencrypted volume/attachment resources from Terraform, their destruction).

